exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Peplink NGxxx/LCxxx VPN-Firewall Open Redirect

Peplink NGxxx/LCxxx VPN-Firewall Open Redirect
Posted Nov 29, 2016
Authored by LiquidWorm | Site zeroscience.mk

Input passed via the '_redirect' GET parameter via 'service.cgi' script on various Peplink VPN-Firewall devices is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

tags | exploit, arbitrary, cgi
SHA-256 | 857b49544d6bb02347eefe4f8fad675fde6301b8ceab69e24b15a2ac153324bc

Peplink NGxxx/LCxxx VPN-Firewall Open Redirect

Change Mirror Download

Peplink NGxxx/LCxxx VPN-Firewall Open Redirect Vulnerability


Vendor: Qingdao Xunbo Information Technology Co., Ltd.
Product web page: http://www.peplink.net
Affected version: PEPLINK NG300 VPN-Firewall
PEPLINK NG320-VPN-Firewall
PEPLINK NG500-VPN-Firewall
PEPLINK NG520-VPN-Firewall
PEPLINK LC500-VPN-Firewall

Summary: The NG500 / 520 is a high-performance VPN server, which is suitable
for small and medium enterprises to use as a VPN center. It is simple to deploy
and high security. At the same time, NG500 / 520 products also integrates advanced
firewall features to support access to computers by group, by region, according to
the strategy, according to rules management; support office network and business
network isolation to ensure data server security. At the same time, NG500 / NG520
support intelligent flow control function, can reserve bandwidth for VPN, to ensure
the fluency of critical applications, to prevent network congestion.

The NG300 / 320 products are cost-effective VPN branch gateway products, support to
drive the entire LAN access to the headquarters network to support LAN TO LAN interconnection.
NG300 / 320 integrated online behavior management function, you can achieve P2P, QQ,
MSN and other application control and site filtering and other functions, support QoS
traffic priority control technology, VPN applications can reserve bandwidth to ensure
the stability of remote enterprise data transmission.

Desc: Input passed via the '_redirect' GET parameter via 'service.cgi' script is not
properly verified before being used to redirect users. This can be exploited to redirect
a user to an arbitrary website e.g. when a user clicks a specially crafted link to the
affected script hosted on a trusted domain.

Tested on: nginx/1.2.9
VPN OS 2.6 UTM Base/027R12-newvpn-3.53r
VPNServer/027R12-vpn-b3.74r


Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience


Advisory ID: ZSL-2016-5376
Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5376.php


24.09.2016

--


GET /service.cgi?_service=get+session&_redirect=http://zeroscience.mk&_sleep=3 HTTP/1.1
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close